{"title":"Detecting Compromised Switches And Middlebox-Bypass Attacks In Service Function Chaining","authors":"Nguyen Canh Thang, Minho Park","doi":"10.1109/ITNAC46935.2019.9077969","DOIUrl":null,"url":null,"abstract":"Service Function Chaining (SFC) provides a special capability that defines an ordered list of network services as a virtual chain and makes a network more flexible and manageable. However, SFC is vulnerable to various attacks caused by compromised switches, especially the middlebox-bypass attack. In this paper, we propose a system that can detect not only middlebox-bypass attacks but also other incorrect forwarding actions by compromised switches. The existing solutions to protect SFC against compromised switches and middlebox-bypass attacks can only solve individual problems. The proposed system uses both probe-based and statistics-based methods to check the probe packets with random pre-assigned keys and collect statistics from middleboxes for detecting any abnormal actions in SFC. It is shown that the proposed system takes only 0.08 ms for the packet processing while it prevents SFC from the middlebox-bypass attacks and compromised switches, which is the negligible delay.","PeriodicalId":407514,"journal":{"name":"2019 29th International Telecommunication Networks and Applications Conference (ITNAC)","volume":"44 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 29th International Telecommunication Networks and Applications Conference (ITNAC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ITNAC46935.2019.9077969","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4
Abstract
Service Function Chaining (SFC) provides a special capability that defines an ordered list of network services as a virtual chain and makes a network more flexible and manageable. However, SFC is vulnerable to various attacks caused by compromised switches, especially the middlebox-bypass attack. In this paper, we propose a system that can detect not only middlebox-bypass attacks but also other incorrect forwarding actions by compromised switches. The existing solutions to protect SFC against compromised switches and middlebox-bypass attacks can only solve individual problems. The proposed system uses both probe-based and statistics-based methods to check the probe packets with random pre-assigned keys and collect statistics from middleboxes for detecting any abnormal actions in SFC. It is shown that the proposed system takes only 0.08 ms for the packet processing while it prevents SFC from the middlebox-bypass attacks and compromised switches, which is the negligible delay.
SFC (Service Function chains)提供了一种特殊的功能,它将网络服务的有序列表定义为虚拟链,使网络更加灵活和可管理。但是,SFC很容易受到交换机受损带来的各种攻击,尤其是middlebox-bypass攻击。在本文中,我们提出了一个系统,不仅可以检测中间盒旁路攻击,还可以检测受损交换机的其他错误转发行为。现有的保护SFC不受交换机破坏和middlebox-bypass攻击的解决方案只能解决个别问题。该系统采用基于探针和基于统计的方法,对随机预分配密钥的探测报文进行检测,并从中间盒中收集统计信息,检测SFC中的异常动作。结果表明,该系统的数据包处理时间仅为0.08 ms,可避免SFC受到绕过中间盒的攻击和交换机受损,延迟可忽略不计。